Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

High‑Severity (CVSS 7.8) Zero‑Day Vulnerability Disclosed in Foxit PDF Software (ZDI‑CAN‑33991)

ZDI has announced an upcoming advisory (ZDI‑CAN‑33991) for Foxit PDF software with a CVSS 7.8 score. The vendor is working on a patch while TrendAI’s filters block exploitation. This underscores the importance of continuous vulnerability‑management and auditable remediation evidence.

LiveThreat™ Intelligence · 📅 September 17, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
zerodayinitiative.com

High‑Severity (CVSS 7.8) Zero‑Day Vulnerability Disclosed in Foxit PDF Software (ZDI‑CAN‑33991)

What Happened – The Zero Day Initiative (ZDI) has published an upcoming advisory (ZDI‑CAN‑33991) for Foxit PDF software with a CVSS 7.8 rating. The vendor has been notified and is developing a patch; TrendAI’s security filters already block exploitation for its customers.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for a continuous vulnerability‑management program that surfaces newly‑disclosed flaws before they are publicly exploitable.
  • Provides a concrete test of the control objective “Maintain up‑to‑date patching and evidence of remediation” that maps to NIST CSF 2.0 (Protect function).
  • Highlights the value of a control‑mapping capability that can automatically collect remediation evidence and feed it into audit‑readiness dashboards.

Who Is Affected – Organizations that deploy Foxit PDF Reader/Editor across desktops, SaaS portals, or embedded PDF workflows (primarily technology, professional services, and government agencies).

Recommended Actions

  • Verify that your asset inventory includes all Foxit installations.
  • Initiate a temporary mitigation (e.g., restrict network access, apply vendor‑provided mitigations) while awaiting the official patch.
  • Capture remediation steps in your continuous control‑assurance platform to demonstrate due‑diligence during audits.

Technical Notes – The advisory does not yet disclose the specific vulnerability type (e.g., memory corruption, privilege escalation) or CVE identifier; it is listed as “upcoming” with a CVSS 7.8 score. TrendAI’s pre‑emptive filters protect customers until the vendor releases a fix. Source: ZDI Upcoming Advisories

📰 Original Source
http://www.zerodayinitiative.com/advisories/upcoming/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →